Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

1.2.2. The Cost of Detection Delay

💡 First Principle: Every hour an attacker goes undetected, they expand their foothold, escalate privileges, and increase the cost of remediation — which means detection speed is a direct measure of security program effectiveness.

The relationship between dwell time and damage is roughly exponential. An attacker detected within hours has typically compromised one or two systems. An attacker with weeks of undetected access may have compromised domain controllers, exfiltrated terabytes of data, and established multiple persistence mechanisms that survive re-imaging of the initial victim.

This is why the CySA+ exam emphasizes Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) as SOC effectiveness metrics. MTTD measures how quickly your monitoring catches an intrusion. MTTR measures how quickly you contain it after detection. Both matter — a fast MTTD with a slow MTTR still allows significant damage after detection.

The implication for analysts: earlier detection requires more sensitive monitoring (catching subtle indicators), while faster response requires pre-built playbooks and rehearsed procedures (so analysts aren't figuring out the process during an active incident).

⚠️ Exam Trap: MTTD and MTTR measure different SOC capabilities. MTTD = detection speed (monitoring quality). MTTR = response speed (process and automation quality). A high MTTD means you're missing indicators. A high MTTR means your response process is slow even when you do detect.

Reflection Question: A SOC detects a ransomware infection 4 hours after it began encrypting files, but takes 48 hours to fully contain it. Which metric is the problem — MTTD or MTTR — and what would you invest in to improve it?

Alvin Varughese
Written byAlvin Varughese
Founder18 professional certifications